sourcegraph records
11 published records for vendor sourcegraph.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 0
- With a fix record
- 63.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-863 Incorrect Authorization2
- CWE-276 Incorrect Default Permissions1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-15 External Control of System or Configuration Setting1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2022-23642Weaponized | Code Injection in Sourcegraphsourcegraph · sourcegraph · CWE-94 | High8.8 | — | 74.3% | Feb 18, 2022 |
35Monitor | CVE-2023-46248No exploit | Overwrite of builtin Cody commands facilitates RCEsourcegraph · cody · CWE-15 | High8.8 | — | 1.1% | Oct 31, 2023 |
32Monitor | CVE-2022-41942No exploit | Sourcegraph vulnerable to Comand Injection via gitserversourcegraph · sourcegraph · CWE-20 | High7.8 | — | 2.8% | Nov 22, 2022 |
29Monitor | CVE-2022-41943No exploit | Incorrect default permissions found in Sourcegraphsourcegraph · sourcegraph · CWE-276 | High7.2 | — | 1.8% | Nov 22, 2022 |
28Monitor | CVE-2022-29171No exploit | Remote Code Execution in sourcegraphsourcegraph · sourcegraph · CWE-74 | High7.2 | — | 1.4% | May 5, 2022 |
26Monitor | CVE-2021-43823No exploit | Side-channel attack in Sourcegraphsourcegraph · sourcegraph · CWE-200 | Medium6.5 | — | 0.8% | Dec 13, 2021 |
26Monitor | CVE-2022-23643No exploit | Side-channel attack in Sourcegraph Code Monitorssourcegraph · sourcegraph · CWE-200 | Medium6.5 | — | 0.8% | Feb 15, 2022 |
24Monitor | CVE-2020-12283No exploit | Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontsourcegraph · sourcegraph · CWE-601 | Medium6.1 | — | 1.3% | Apr 30, 2020 |
17Monitor | CVE-2021-32787No exploit | Low risk information disclosure in Sourcegraphsourcegraph · sourcegraph · CWE-200 | Medium4.3 | — | 0.6% | Aug 2, 2021 |
17Monitor | CVE-2022-31154No exploit | Indirect Object Access in Sourcegraph Code Monitoringsourcegraph · sourcegraph · CWE-863 | Medium4.3 | — | 0.5% | Aug 1, 2022 |
17Monitor | CVE-2022-31155No exploit | Unauthorized overwriting of saved searches in Sourcegraphsourcegraph · sourcegraph · CWE-863 | Medium4.3 | — | 0.5% | Aug 1, 2022 |
- CVE-2022-2364257Plan
Code Injection in Sourcegraph
HighCVSS 8.8WeaponizedEPSS 74%sourcegraph · sourcegraphFeb 18, 2022
- CVE-2023-4624835Monitor
Overwrite of builtin Cody commands facilitates RCE
HighCVSS 8.8No exploitEPSS 1%sourcegraph · codyOct 31, 2023
- CVE-2022-4194232Monitor
Sourcegraph vulnerable to Comand Injection via gitserver
HighCVSS 7.8No exploitEPSS 3%sourcegraph · sourcegraphNov 22, 2022
- CVE-2022-4194329Monitor
Incorrect default permissions found in Sourcegraph
HighCVSS 7.2No exploitEPSS 2%sourcegraph · sourcegraphNov 22, 2022
- CVE-2022-2917128Monitor
Remote Code Execution in sourcegraph
HighCVSS 7.2No exploitEPSS 1%sourcegraph · sourcegraphMay 5, 2022
- CVE-2021-4382326Monitor
Side-channel attack in Sourcegraph
MediumCVSS 6.5No exploitEPSS 1%sourcegraph · sourcegraphDec 13, 2021
- CVE-2022-2364326Monitor
Side-channel attack in Sourcegraph Code Monitors
MediumCVSS 6.5No exploitEPSS 1%sourcegraph · sourcegraphFeb 15, 2022
- CVE-2020-1228324Monitor
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/front
MediumCVSS 6.1No exploitEPSS 1%sourcegraph · sourcegraphApr 30, 2020
- CVE-2021-3278717Monitor
Low risk information disclosure in Sourcegraph
MediumCVSS 4.3No exploitEPSS 1%sourcegraph · sourcegraphAug 2, 2021
- CVE-2022-3115417Monitor
Indirect Object Access in Sourcegraph Code Monitoring
MediumCVSS 4.3No exploitEPSS 0%sourcegraph · sourcegraphAug 1, 2022
- CVE-2022-3115517Monitor
Unauthorized overwriting of saved searches in Sourcegraph
MediumCVSS 4.3No exploitEPSS 0%sourcegraph · sourcegraphAug 1, 2022